PNNL Study Targets Authentication Vulnerability of Connected Lighting Systems

CEW 13 Controls 400

July 3, 2020
By Craig DiLouie

The U.S. Department of Energy has released the results of a study examining authentication vulnerabilities in connected lighting systems (CLS). Particularly as emerging CLS incorporate distributed intelligence, network interfaces and sensors, they can serve as data-collection platforms that enable a wide range of valuable new capabilities as well as greater energy savings in buildings and cities. However, CLS technology is currently at an early stage of development, and its increased connectivity introduces cybersecurity risks that are new to the lighting industry and must be addressed for successful integration with other systems.

There are numerous existing frameworks and guidelines for evaluating cybersecurity vulnerability, such as the National Institute of Standards and Technology (NIST) Cybersecurity Framework, the NIST 800 series comprising more than 150 resources, the International Electrotechnical Commission (IEC) 62443 series, International Organization for Standardization 27001 and 27002, Unified Facilities Criteria (UFC) 4-010-06, and UL 2900-1. Furthermore, a variety of testing resources are widely available, including the Open Web Application Security Project (OWASP) Testing Guide. While these frameworks, guidelines, and tests may apply to CLS in whole or in part, there is currently no mandatory requirement for cybersecurity testing or certification.

Photo: Conceptual representation of multiple connected lighting systems, showing common system architecture variations and technology implementations:

CEW 13 Multiple Connection Lighting System 400

The lighting industry, including technology developers and specification organizations, is currently evaluating the suitability of existing frameworks and guidelines for CLS. To support these efforts, the Pacific Northwest National Laboratory (PNNL) is conducting a series of studies intended to educate lighting-industry stakeholders on specific cybersecurity practices and characterize their implementation in commercially available CLS with varying system architectures, network-communication technologies, and degrees of maturity.

The first study explores authentication practices and their implementation in multiple CLS. A total of 18 tests were developed by UL and implemented in PNNL’s Connected Lighting Test Bed (CLTB). The tests explore the implementation of basic authentication best practices as well as known technology-specific best practices. As a result, not all tests are applicable to all CLS.

A total of 40 out of 72 potential tests (4 CLS, 18 potential tests each) were applicable for 4 evaluated CLS, and the CLS collectively passed 26 of the 40 tests (65%). While pass/fail ratio is a simple way of reporting test results, it is not really a relevant metric. Cybersecurity vulnerability testing is a risk-analysis practice; the relevance of passing or failing a certain test is best evaluated in concert with an understanding of the risk associated with that vulnerability in a specific implementation. Nevertheless, pass/fail ratios give some indication of the range of performance found in market-available CLS.

Based on the limited results of this study, it appears that the CLS being brought to market have varying levels of authentication vulnerability. It is hoped that these evaluations will support and perhaps accelerate industry discussions on the risks of specific security vulnerabilities, what vulnerabilities should be addressed by lighting-specific best practices in development, and whether any such practices should be included in voluntary lighting standards.

PNNL plans to conduct more authentication testing and to work with UL and other cybersecurity experts to explore authorization vulnerabilities. PNNL will bring these results to the ANSI C137 Lighting Systems ad-hoc working group focusing on cybersecurity vulnerability, for consideration in the creation and development of new standards.

Go HERE for the report

Craig DiLouie, LC, is Education Director for the Lighting Controls Association. Reprinted with permission of the Lighting Controls Association, www.lightingcontrolsassociation.org

Photo by jaydeep_ on Pixabay

Related Articles


Changing Scene

  • Jan 14, 2026 - GVA Lighting Promotes Gareth Bruce to Vice President – Sales & Marketing

    GVA Lighting Promotes Gareth Bruce to Vice President – Sales & Marketing

    GVA Lighting is pleased to announce the promotion of Gareth Bruce to Vice President of Sales and Marketing, effective December 5th, 2025. Gareth joined GVA in May 2024 as Regional Sales Manager – Southeast, bringing more than two decades of lighting industry experience from Philips / Signify. He was promoted to Director of North American Sales in September 2024 and has since… Read More…

  • Jan 14, 2026 - Intralec Electrical Products Proudly Representing SATCO NUVO Lighting Solutions

    Intralec Electrical Products Announces SATCO NUVO Representation

    Intralec is proud to represent SATCO | NUVO lighting solutions for commercial, residential, and industrial applications. SATCO | NUVO is a major supplier of lighting products, with solutions for nearly every lighting market across the commercial, residential, and industrial landscape. With over 1.5 million square feet of inventory throughout North America and thousands of products… Read More…


Design

  • EB Horsman: Can LED Roadway Lighting Enhance Road Safety & Efficiency?

    EB Horsman: Can LED Roadway Lighting Enhance Road Safety & Efficiency?

    At EB Horsman, they recognize that effective roadway lighting is a crucial component of public safety. With Lumec’s LED roadway lighting solutions, communities can ensure reliable, high-quality illumination that supports safer travel for everyone, day or night, while also improving energy efficiency and long-term operational performance. High-quality roadway lighting is a critical component of public… Read More…

  • Prolux Lighting & Controls: Project Spotlight – Residential House in the Kootenays

    Prolux Lighting & Controls: Project Spotlight – Residential House in the Kootenays

    Have a look at this custom residential home in the Kootenays, where Prolux utilized the HALO RL6 Slope Ceiling Direct Mount fixtures by Cooper Lighting Solutions designed specifically for sloped ceilings. These luminaires provided consistent, high-quality illumination while maintaining a clean, low-profile ceiling aesthetic. Their direct-mount design allowed for seamless integration throughout the home, supporting… Read More…


New Products

  • Philips Hue Transforms Lighting Design with the Hue SpatialAware Feature That Understands Your Space

    Philips Hue Transforms Lighting Design with the Hue SpatialAware Feature That Understands Your Space

    Signify is introducing Hue SpatialAware, which will transform how Philips Hue users experience light scenes. This feature analyzes the layout of your room and the placement of your Philips Hue lights to create the optimal lighting experience tailored to your unique environment. It’s like having a lighting designer in your pocket, allowing you to experience… Read More…

  • Liteline: New LUNA Fire Driver for 3.5″ Fixture

    Liteline: New LUNA Fire Driver for 3.5″ Fixture

    Introducing a new lower-cost driver option for LUNA Fire! This 12W, 120V driver with TRIAC/ELV dimming is designed to significantly reduce cost while maintaining performance, giving you more flexibility.  The LUNA Fire meets UL 1598 / 2108/ 263, CSA C22.2 #250.0 / 250.2, and ULC-S101 safety and building construction requirements granting inherent 2-hour fire-rated protection. It… Read More…